Re: How to fix problems with the sashiko review model

James Bottomley <[email protected]> Wed, 22 Jul 2026 11:55:36 -0400
Newsgroups dev.linux.lists.ksummit,dev.linux.lists.sashiko-reviews,org.kernel.vger.linux-scsi
Message-ID <9a107be6c6041e3ce892217096c8fba7c9489849.camel@HansenPartnership.com>
On Wed, 2026-07-22 at 11:39 -0400, Steven Rostedt wrote:
> On Wed, 22 Jul 2026 16:25:03 +0200
> Johannes Berg <[email protected]> wrote:
>=20
> > There's also a risk thing - if you erroneously get a report for
> > SCSI (as you did, IIUC) then you can opt out at that point and not
> > worry about it again.
> >=20
> > If we erroneously _don't_ get a report for something that didn't
> > speak up because they're not on the list, didn't dare say anything,
> > didn't pay attention, etc. then nobody ever knows until someone
> > starts exploiting it?
>=20
> I agree with Johannes here. It's one thing to get an annoying report
> that says "You can be compromised by your hardware" when the hardware
> is trusted. I have the same issue with boot parameters. But I rather
> opt-in than have the case that I'm the odd one out where my hardware
> is not trustworthy, but I don't know I have to take action to have it
> checked.

The thing is it's not just sashiko.  Various AI driven patchers seem to
be using the prompts, which has lead to a slew of malicious hardware
fixes being sent to linux-scsi and I'm getting a bit worn out replying
to them saying that's not in our threat model.

So I figured why not fix the problem at source.

Regards,

James